38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-6018
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-12724
WP DeskLite Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-2387
AFI – The Easiest Integration Plugin Web Database Windows
6.1
MEDIUM
EPSS
44.8%
2024 CWE-89 1 PoC

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries and subsequently inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing

CVE-2023-30148
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and /sourcefiles/blockhtml.php.

CVE-2023-42307
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

CVE-2023-29623
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
27.4%
2023 1 PoC

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

CVE-2020-35831
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2020 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

CVE-2024-3867
Tainacan Interface Web Windows
6.1
MEDIUM
EPSS
22.7%
2024 CWE-79 1 PoC

The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-3548
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-29602
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.

CVE-2022-38553
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
30.7%
2022 2 PoCs

Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.

CVE-2022-4552
FL3R FeelBox Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2022-43369
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

CVE-2024-3368
All in One SEO Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2438
UserPro - Community and User Profile WordPress Plugin Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthenticated attackers to update the user meta and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-28277
Software Genérico Web
6.1
MEDIUM
EPSS
0.5%
2024 2 PoCs

In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.

CVE-2023-2337
ConvertKit Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13010
WP Foodbakery Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 CWE-79 1 PoC

The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on the 'search_type' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2020-24706
Software Genérico Web
6.1
MEDIUM
EPSS
0.7%
2020 1 PoC

An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics through 5.6.0, and IoT Server 3.1.0.

CVE-2020-2562
Primavera Portfolio Management Web Database
6.1
MEDIUM
EPSS
0.9%
2020 1 PoC

Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerabi